---
title: "Cyber Security News Update, Week 11 of 2022 | DuoCircle"
description: "The cyber-world never sleeps or remains dormant."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-11-of-2022/"
---

Quick Answer

Week 11 of 2022 covered: HelpSystems' acquisition of MDR provider Alert Logic (4,000+ customers), continuing its cybersecurity buying spree that already included Tripwire ($350m), Vera, Digital Guardian, PhishLabs, Clearswift, Beyond Security, Agari, and Digital Defense; Ukraine's acceptance as a NATO CCDCOE contributing participant ahead of formal NATO membership consideration; a Freedom of Information Act release showing the BBC faced 383,278 phishing, spam, and malware attacks daily between October 2021 and January 2022 (47 million total, including 291,042 phishing emails and 70,589 malware attacks); Mozilla's out-of-band patches for two actively exploited Firefox zero-days, CVE-2022-26485 (XSLT use-after-free) and CVE-2022-26486 (WebGPU IPC sandbox escape), with CISA mandating federal patches by March 21, 2022; Google Workspace updates that now include the commenter's email address in comment notifications, after a year of attacker abuse using fake-named comment mentions; and an FBI/CISA alert on Ragnar Locker breaching 52 US organizations across 10 critical infrastructure sectors, with operators stopping Kaseya and ConnectWise to evade detection.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-11-of-2022%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2011%20of%202022&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-11-of-2022%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-11-of-2022%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-11-of-2022%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2011%20of%202022 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2011%20of%202022&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-11-of-2022%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2022/03/spf-record-tester-6710.jpg) 

_The cyber-world never sleeps or remains dormant_. By the time you finish reading this post, an attack would have compromised some system somewhere, and that is precisely why it is so important for us to stay abreast of the [weekly cybersecurity headlines](/announcements). Following are the cyber incidents in headlines this week.

## HelpSystems All Set to Acquire Alert Logic

Since last year, _the Minnesota-based software firm HelpSystems has been on a cybersecurity buying spree_. Its previous purchases include Tripwire (acquired for **$350 million**), data protection firm Vera, **data loss prevention** specialists Digital Guardian, threat intelligence company [PhishLabs](https://www.phishlabs.com/), content protection firm Clearswift, vulnerability assessment, and compliance solutions firm Beyond Security, [email security](/) company Agari and vulnerability management company Digital Defense. HelpSystems has recently expressed interest in acquiring the Texas-based managed detection and response (MDR) services provider, Alert Logic.

While the terms of the agreement have not been disclosed, _HelpSystems takes pride in welcoming the cybersecurity experts at Alert Logic into its own team_. The latter has **over 4,000 customers** globally and specializes in augmenting customers’ existing **cybersecurity resources** by taking care of SaaS, cloud, protect on-premise and hybrid environments. It further ensures that regulatory requirements are always met, including HIPAA HITECH, PCI DSS, GDPR, SOC 2, Sarbanes-Oxley (SOX), NIST 800-171, and 800-53, COBIT, ISO 27001, etc. Alert Logic was started in 2002 and was last owned by the private equity firm Welsh, Carson, Anderson & Stowe in 2013.

_HelpSystems foresees a fast change in the cybersecurity world_ and therefore believes in staying ahead of the rest in the race to ensure enhanced and better **cybersecurity tools** for customers. The latest Alert Logic acquisition attempts to better its position in the same interest. HelpSystems is hopeful the merger will help both companies serve their customers better.

## Ukraine To Be An Accepted NATO CCDCOE Member

With the ongoing war and cyberattacks targeted at Ukraine, the nation has been accepted as a member of the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE). This [CCDCOE membership](https://ccdcoe.org/news/2022/ukraine-to-be-accepted-as-a-contributing-participant-to-nato-ccdcoe/) comes before Ukraine’s formal North Atlantic Treaty Organization (NATO) membership. _CCDCOE is a cyberdefense hub that is used by member nations for cybersecurity-related training or research purposes_. The CCDCOE membership shall enable Ukraine to access and share the cyber-expertise of other NATO member nations, thereby strengthening its own **national cybersecurity** foothold.

This move benefits both Ukraine and NATO CCDCOE as the former’s first-hand experience in dealing with major threat actor groups can be used for research, training, and exercises. _Ukraine was to join the NATO Alliance back in 2008, but the matter took a backseat owing to Russian objections_. However, NATO re-announced Ukraine’s consideration of the NATO membership at a June 2021 summit which is likely to happen after it goes through the Membership Action Plan.

## BBC Constantly Targeted by Phishing And Malware Attacks

[![Phishing And Malware Attacks](https://media.mailhop.org/duocircle/images/2022/03/spf-validator-6077.jpg)](https://media.mailhop.org/duocircle/images/2022/03/spf-validator-6077.jpg)

Official statistics obtained through a Freedom of Information Act (FOI) request revealed that between 1st October 2021 and January 2022, the British Broadcasting Corporation (BBC) underwent **383,278 phishing, spam**, and malware attacks daily. A Parliament Street think tank analyzed these figures and found that around **50 million** malicious emails were sent to the BBC during this period. The [daily attack average on BBC](https://www.helpnetsecurity.com/2022/03/07/bbc-malicious-email-attacks/) has increased from 283,597 phishing emails in 2020 to 383,278 [phishing emails](/phishing-protection/how-to-stop-phishing-emails-and-protect-your-organization-from-cyber-criminals/) in 2022.

Of the **47,143,313 malicious emails** sent to BBC in the four months between October 2021 and January 2022, 291,042 were categorized as phishing emails and 70,589 as [malware attacks](/resources/upatre-malware-spams). This comes down to _574 malware attacks and 2,366 phishing emails on BBC employees every day._ Cybersecurity experts opine that this increase in the number of attacks is caused by the rising threat of Omicron and the ongoing busy shopping periods.

A common reason for launching **phishing campaigns** is to steal the login credentials of renowned journalists. And BBC becomes an attractive target for cybercriminals with the possibility of stealing nationally, politically, socially, or economically relevant data and credentials. Thus, there is a need for organizations to alert and [train their employees](/phishing-awareness-training) against potential **phishing attacks**.

## Mozilla Patches Two Vulnerabilities in Firefox Web Browser

_Mozilla has launched out-of-band software updates for its Firefox web browser to patch two high-impact security vulnerabilities_ (CVE-2022-26485 and CVE-2022-26486). Reportedly, both these [zero-day vulnerabilities](https://thehackernews.com/2022/03/2-new-mozilla-firefox-0-day-bugs-under.html) are being actively exploited. The CVE-2022-26485 and CVE-2022-26486 vulnerabilities affect the WebGPU inter-process communication (IPC) Framework and the Extensible Stylesheet Language Transformations (XSLT) parameter processing.

While CVE-2022-26485 could lead to an exploitable use-after-free vulnerability by removing an XSLT parameter during processing, CVE-2022-26486 could lead to an exploitable sandbox escape and a use-after-free vulnerability by sending an unexpected message in the WebGPU IPC framework. _Mozilla was notified of the open exploitation of these two bugs_, but it has refrained from sharing the technical details of the intrusions. Cybersecurity experts at Qihoo 360 ATA -Liu Jialei, Wang Gang, Du Sihang, Yang Kang, and Huang Yi were the first to discover and report the flaws.

Mozilla users are advised to upgrade to Firefox 97.0.2, Focus 97.3.0, Firefox ESR 91.6.1, Thunderbird 91.6.2, and Firefox for Android 97.3.0\. _CISA also released an update asking federal agencies to get patches for these vulnerabilities_ by 21st March 2022.

## Google Workspace Comment Notifications to Now Include Sender’s Email

[![Google Workspace Comment Notifications](https://media.mailhop.org/duocircle/images/2022/03/spf-record-generator-6787.jpg)](https://media.mailhop.org/duocircle/images/2022/03/spf-record-generator-6787.jpg)

In line with the news that recently made it to the headlines, which said that _adversaries have been exploiting a flaw in the comment feature of Google Workspace for over a year now_, [Google has incorporated some changes](https://www.securityweek.com/google-fights-phishing-updated-workspace-notifications) in its Google Workspace comment notifications. This step is to ensure [ransomware protection](/email-security/5-ways-you-protect-your-business-from-ransomware/) for GSuite users.

Earlier, when someone added a comment in a Google Workspace document by mentioning someone, the auto email notification would only include the commenter’s name and the comment. Using this blindspot, hackers would create fake email addresses and send malware to users, the only action needed from the user is opening the link in the email. Hence, _Google has introduced this new feature wherein the email notification includes the commenter’s email address_. This move shall help users evaluate where an email comes from legitimate sources. Google announced that this feature would be automatically added to all legacy G Suite Basic, Google Workspace, and Business customers in a couple of weeks. The update will also be released for personal Google account users.

## FBI Warns of Growing Ragnar Locker Attacks

_The FBI recently notified that the Ragnar Locker ransomware group had attacked more than 50 US-based organizations_ in the recent past. Most of these victims come from critical infrastructure sectors. Therefore, the CISA and the FBI had jointly released an alert recently to provide a background on how [Ragnar Locker operates](https://web.archive.org/web/20240918050317/https://cyware.com/news/ragnar-locker-breached-52-organizations-and-counting-fbi-warns-0588d220/). The alert also mentioned the [ransomware protection strategies](/email-security/5-ways-you-protect-your-business-from-ransomware/) organizations could use against Ragnar.

Reportedly, **52 organizations** across ten critical infrastructure sectors (including manufacturing, energy, financial services, IT, government, etc.) were targeted by Ragnar Locker. The alert also mentioned the Bitcoin and email addresses used to collect ransom and contact victims. In a typical attack, Ragnar operators stop remote management software such as Kaseya and ConnectWise to evade detection and make sure that logged-in admins cannot intrude in the deployment process. In this notification, _the FBI encourages security professionals to share any information they may have on the attack patterns_. These often accelerate the investigation process and help in identifying the attackers.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-11-of-2022%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2011%20of%202022&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-11-of-2022%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-11-of-2022%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 11 of 2022","description":"The cyber-world never sleeps or remains dormant.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-11-of-2022/","datePublished":"2022-03-19T21:51:43.000Z","dateModified":"2025-06-03T17:59:08.000Z","dateCreated":"2022-03-19T21:51:43.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-11-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1205,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/03/spf-record-tester-6710.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 11 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-11-of-2022/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 11 of 2022","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-11-of-2022/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 11 of 2022","description":"The cyber-world never sleeps or remains dormant.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-11-of-2022/","datePublished":"2022-03-19T21:51:43.000Z","dateModified":"2025-06-03T17:59:08.000Z","dateCreated":"2022-03-19T21:51:43.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-11-of-2022/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1205,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/03/spf-record-tester-6710.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
